Junglewise Threat Intelligence

CVE-2026-12955: WordPress GDPR Cookie Consent unauthorized data modification

CVE-2026-12955 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Technologies: WPLegalPages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Vendors: WPLegalPages.

Executive brief

The GDPR Cookie Consent plugin for WordPress, which helps websites manage legal compliance banners, contains a security flaw that allows low-level users to change administrative settings. Specifically, an attacker with a basic account (like a subscriber) can modify the schedule for when the plugin scans the website for cookies. While this does not directly expose sensitive customer data, it allows unauthorized users to interfere with administrative functions and website compliance operations.

Technical details

The GDPR Cookie Consent plugin for WordPress is vulnerable to an authorization bypass due to a missing capability check and missing nonce (CSRF) verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function, which handles the wp_ajax_gcc_save_schedule_scan AJAX action. This vulnerability allows authenticated attackers with Subscriber-level permissions or higher to modify the gdpr_scan_schedule_data option. This option controls the plugin's cookie scan schedule, a function intended to be restricted to administrators with the manage_options capability. The issue is addressed in version 4.3.7.

Affected products

  • wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent up to, and including, 4.3.6

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats